Uploaded image for project: 'Sling'
  1. Sling
  2. SLING-9770

XSS API encodeForCSSString should sometimes leave the '>' character alone

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Open
    • Major
    • Resolution: Unresolved
    • XSS Protection API 2.2.6
    • None
    • XSS Protection API
    • None

    Description

      while

      xssApi.encodeForCSSString should righteously encode "JavaScrIpt some text>" into "JavaScrIpt some text
      3e"it should leave ".foo > .bar { some rule }" alone as changing here the '>' character will break the CSS

      Attachments

        Activity

          People

            Unassigned Unassigned
            npeltier Nicolas Peltier
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

            Dates

              Created:
              Updated: